|
||
A new examination of public Certificate Transparency (CT) logs has identified 32 unauthorized HTTPS certificates issued during attacks on the country-code top-level domains (ccTLDs) of Ghana, Sierra Leone and American Samoa. The findings provide a more detailed account of incidents in which attackers manipulated authoritative DNS records to obtain trusted certificates for domains belonging to Google and other major organizations.
The 32 certificates were issued between September 22 and 27. According to an October 8 report by iTnews, the publication identified the certificates by comparing public CT records with Chrome’s certificate blocklist. The analysis suggests that Ghana’s .gh namespace was compromised first, on September 22, followed by Sierra Leone’s .sl on September 25 and American Samoa’s .as on September 27. Most certificates associated with each incident were issued within approximately 90 minutes.
The certificates reportedly included wildcard certificates issued through Let’s Encrypt and Sectigo’s ZeroSSL service. iTnews also identified a certificate issued through Cloudflare’s certificate authority for a domain associated with another major technology company. The publication’s count has not been independently reproduced.
The attacks exploited control over authoritative DNS. In an October 6 security disclosure, Google confirmed that attackers had altered DNS records within the three affected namespaces and obtained certificates covering several Google domains and domains belonging to other organizations.
Certificate authorities rely on domain-control validation to establish whether an applicant is authorized to obtain a certificate. When attackers control the DNS records used in that process, they can potentially satisfy validation checks without authorization from the legitimate domain owner.
Google emphasized that the incidents did not involve a compromise of its own systems and said it had no reason to believe the issuing certificate authorities acted improperly.
Chrome blocked the unauthorized certificates. Google said it used Chrome’s CRLSet mechanism to prevent affected certificates from being trusted and worked with issuing authorities to secure their revocation. It subsequently identified additional potentially affected organizations through CT monitoring and extended its blocking measures.
The certificates have since been revoked, according to iTnews. Google nevertheless cautioned that browser-side protections cannot guarantee detection of every affected domain or protect users of all browsers and applications.
The incidents expose a dependency between DNS integrity and HTTPS trust. A certificate can be issued through an otherwise legitimate validation process when the underlying DNS information has been compromised. If attackers can also redirect traffic, an unauthorized certificate may enable convincing impersonation of the affected website.
Google recommends that domain owners continuously monitor CT logs across their entire domain portfolios, including parked domains and regional registrations. It also advises deploying restrictive Certification Authority Authorization (CAA) records with account-specific controls.
Google noted that CAA records cannot necessarily prevent issuance during an active DNS hijack, but properly configured restrictions can help prevent further unauthorized issuance after legitimate DNS control is restored.
The precise methods used to compromise the three ccTLD namespaces remain undisclosed. iTnews reported receiving no responses from the affected registry operators before publication. The registry-level incident timelines, the full inventory of affected domains and the extent of any resulting traffic interception have not been established publicly.
Sponsored byDNIB.com
Sponsored byRadix
Sponsored byIPv4.Global
Sponsored byWhoisXML API
Sponsored byCSC
Sponsored byVerisign
Sponsored byVerisign